Exness, a leading foreign exchange broker in the financial services field, is looking for an Infrastructure Security Engineer to join our IT Security function in Limassol, Cyprus with the objective to identify existing and emerging security threats and protect Exness Group of Companies from them, maintain business continuity and regulatory compliance in respective areas.
Infrastructure Security Engineer reports to Infrastructure Security Team Lead.
- Work directly with the business units to facilitate risk assessment and risk management processes.
- Maintain effective communication and coordination with Product Development and Operations teams in security-related areas.
- Ensure that information assets and technologies are properly protected, which includes the following:
- Managing information security controls;
- Enforcing compliance with these controls and technology-related regulatory requirements;
- Participating in internal and external audits;
- Data loss and fraud prevention. Making sure the staff doesn't misuse data;
- Manage personal data protection measures (including GDPR);
- Development of security policies and procedures.
- Review architecture, implementation and operations of IT systems from security perspective.
- Identity and access management. Ensuring that only authorized people have access to restricted data and systems. Maintain least privilege approach;
- Management of Security incidents. Investigations and forensics;
- Process events generated by security tools: WAF, VPN, SIEM, etc.
- Management and development of security education program for employees (at onboarding and ongoing).
- 5+ years of experience in Information Security or other IT roles.
- Ability to leverage business communication skills to inform, convince, and educate employees to enable effective information security activities and processes.
- Knowledge of most common vulnerabilities and ways of protective measures from exploiting them.
- Hands-on experience with modern information protection systems, including open source products.
- General knowledge in the technologies below with expert level in few of them:
- Experience in administering of Linux and Windows systems;
- Understanding of security aspects of virtualization, containerization (Docker) and cloud services (AWS);
- Cryptography foundations. Knowledge of X509 standard and experience with PKI administration;
- Broad spectrum of technical knowledge in the following areas (the list is not exhaustive): Linux family, Docker, Kubernetes, vSphere, AWS, Vault, LDAP, Cisco ASA, Microsoft WIndows / AD, SSO;
- Audits: internal and external.
- General acquaintance with regulatory frameworks and compliance requirements associated with financial services is a plus.
- English and Russian language (Intermediate or higher).
Would be a plus:
- ITSM fundamentals, project management.
- Any industry certifications.
- Security forensics experience.
For remote employees:
- Medical insurance for employees.
- Compensation for sports activities.
- Trip to Cyprus office to get to know your Team (once a year).
For employees who want relocate:
- Outstanding relocation package to Cyprus.
- New branded corporate Mini Cooper Countryman S for the employee and the family.
- Medical insurance for employees and immediate family members.
- Company fitness center for employees and their spouses.
- Parking near the office or a bus pass.
- Kindergarten/school compensation program.
- The best view of the sea from our own roof bar.
- We support the relocation of our candidates by providing visa and migration processing and do our best to help them to be successful in the company.